XSS Vulnerability in Action View Tag Helpers for Ruby on Rails
CVE-2022-27777

6.1MEDIUM

Key Information:

Vendor
CVE Published:
26 May 2022

What is CVE-2022-27777?

A Cross-Site Scripting vulnerability exists in the Action View tag helpers of Ruby on Rails, specifically in versions greater than or equal to 5.2.0 and less than 5.2.0. This flaw allows attackers to inject malicious content into web applications by manipulating input into specified attributes. If an attacker can control specific input, they can potentially execute arbitrary script code in the context of the user's session, leading to the compromise of sensitive data and user impersonation.

Affected Version(s)

https://github.com/rails/rails 7.0.2.4, 6.1.5.1, 6.0.4.8, 5.2.7.1

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.